Quick Summary
AllegedExecutive Summary
Interlock listed Southeastern Oklahoma State University (SE) on its dark web portal on August 19, 2026, marking the group’s latest move in a sustained campaign targeting US public-sector education. This listing was identified through SOCRadar’s Dark Web Monitoring service. SE, a regional public university in Durant, Oklahoma, serves approximately 4,000 students and utilizes federated identity and Blackboard-integrated systems. The university’s profile aligns with Interlock’s typical targets, characterized by lower resource allocation, a large external user base, and extended remediation cycles. Over the 60 days prior to this listing, Interlock has demonstrated a focused pattern of targeting US public-sector organizations, including universities, hospital networks, and government agencies. The group specifically targets federated identity infrastructure, aiming for environments where a single compromised Single Sign-On (SSO) account can grant access to multiple critical systems such as email, HR, and student databases simultaneously. Previous Interlock victims in the education sector include similar regional public universities and community colleges, with a consistent denominator being institutions lacking enterprise-tier security operations.
Technical Analysis
SOCRadar’s stealer-log telemetry revealed 25 records associated with the se.edu domain, classified as severe. Ten of these records directly targeted SE’s infrastructure, specifically the ADFS federated identity portal (adfs.se.edu) and the Blackboard learning management system (blackboard.se.edu). The remaining 15 records were of unclear organizational affiliation. The ADFS portal is identified as the primary concern, acting as the main identity broker for institutional SSO. Credentials associated with adfs.se.edu could grant an attacker access to SE’s entire connected application ecosystem without necessitating further exploitation. The observed data freshness window ranges from July 21 to August 20, 2026, extending up to the publication date of the listing. The presence of these stealer-log records does not definitively confirm that Interlock successfully utilized these specific credentials for an intrusion. However, the ADFS records, dated up to the day of the listing, align with the typical pre-staging timeline observed in such incidents. This pattern suggests a potential pathway for attackers to gain access to sensitive systems. The association of these credentials with the ADFS portal, a critical component for institutional SSO, highlights a significant potential risk. The evidence indicates a need for immediate action. Organizations are advised to force-rotate all accounts within the identified sample of compromised credentials. Furthermore, auditing sign-in logs for the adfs.se.edu portal is crucial to detect anomalous access patterns. The ADFS portal should be treated as the primary investigation target to understand the extent of any potential compromise and to mitigate further risks.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.